The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Mar 20, 2015 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Mar 19, 2015 |
| Cisco Xr Os | — | Upgrade to the latest version of Cisco IOS-XR to resolve this vulnerability. | May 19, 2021 | Mar 20, 2015 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Mar 19, 2015 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Mar 19, 2015 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Mar 19, 2015 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Mar 20, 2015 | Mar 19, 2015 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 2.0.6-0.175.2.9.0.4.0 on Solaris 11.2Upgrade library/security/openssl to version 1.0.1.13-0.175.2.9.0.4.0 on Solaris 11.2 | May 29, 2017 | Mar 19, 2015 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.0R11Update Pulse Connect Secure to version 7.4R13.4Update Pulse Connect Secure to version 7.1R22.1Update Pulse Connect Secure to version 8.1R3.1 | Oct 28, 2020 | Mar 19, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub